Latest CVE Feed
-
8.1
HIGHCVE-2025-3055
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_avatar_ajax() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated atta... Read more
Affected Products :- Published: Jun. 05, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2025-3054
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 4.1.3. This makes it possible for authenticated attackers, with ... Read more
Affected Products :- Published: Jun. 05, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authentication
-
8.8
HIGHCVE-2025-5638
A vulnerability has been found in PHPGurukul Notice Board System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin-profile.php. The manipulation of the argument mobilenumber leads to sql injectio... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5637
A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component SYSTEM Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The e... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5636
A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SET Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. ... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-1793
Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially leading to unauthorized access to data of other users de... Read more
Affected Products : llamaindex- Published: Jun. 05, 2025
- Modified: Jul. 30, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5635
A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of the component PLS Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5634
A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component NOOP Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-5633
A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/users.php. The manipulation of the argument delete... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-5632
A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/users.php. The manipulation of the argume... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5631
A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been classified as critical. Affected is an unknown function of the file /publicposts.php. The manipulation of the argument post leads to sql inje... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Injection
-
10.0
HIGHCVE-2025-5630
A vulnerability has been found in D-Link DIR-816 1.10CNB05 and classified as critical. This vulnerability affects unknown code of the file /goform/form2lansetup.cgi. The manipulation of the argument ip leads to stack-based buffer overflow. The attack can ... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-5629
A vulnerability, which was classified as critical, was found in Tenda AC10 up to 15.03.06.47. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg of the component HTTP Handler. The manipulation of the argument startIp/endIp le... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption
-
5.8
MEDIUMCVE-2025-49466
aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the name of an attachment part,... Read more
Affected Products :- Published: Jun. 05, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Path Traversal
-
4.0
MEDIUMCVE-2025-48432
An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially manipulate log output via crafted URLs. This may lead t... Read more
Affected Products : django- Published: Jun. 05, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-5628
A vulnerability, which was classified as problematic, has been found in SourceCodester Food Menu Manager 1.0. Affected by this issue is some unknown functionality of the file /index.php of the component Add Menu Handler. The manipulation of the argument n... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-5627
A vulnerability classified as critical was found in code-projects Patient Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /sputum_form.php. The manipulation of the argument itr_no leads to sql injection... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5626
A vulnerability classified as critical has been found in Campcodes Online Teacher Record Management System 1.0. Affected is an unknown function of the file /admin/edit-subjects-detail.php. The manipulation of the argument editid leads to sql injection. It... Read more
Affected Products : online_teacher_record_management_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-5625
A vulnerability was found in Campcodes Online Teacher Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /search-teacher.php. The manipulation of the argument searchteacher leads to sql inje... Read more
Affected Products : online_teacher_record_management_system- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Injection
-
10.0
HIGHCVE-2025-5624
A vulnerability was found in D-Link DIR-816 1.10CNB05. It has been declared as critical. This vulnerability affects the function QoSPortSetup of the file /goform/QoSPortSetup. The manipulation of the argument port0_group/port0_remarker/ssid0_group/ssid0_r... Read more
- Published: Jun. 05, 2025
- Modified: Jun. 06, 2025
- Vuln Type: Memory Corruption